docs: add more specific steps and information about oidc refresh tokens (#18336)

closes https://github.com/coder/coder/issues/18307

relates to https://github.com/coder/coder/pull/18318

preview:
-
[refresh-tokens](https://coder.com/docs/@18307-refresh-tokens/admin/users/oidc-auth/refresh-tokens)
-
[configuring-okta](https://coder.com/docs/@18307-refresh-tokens/tutorials/configuring-okta)
~(not sure why @Emyrk 's photo is so huge there though)~ ✔️
- [x] removed from
[idp-sync](https://coder.com/docs/@18307-refresh-tokens/admin/users/idp-sync)

to do:
- move keycloak
- add ping federate and azure
- edit text (possibly placeholders for now - I want to see how it all
relates and edit it again. right now, there's a note about the same
thing in every section in way that's not super helpful/necessary)
- ~convert some paragraphs to OL~ calling this out of scope for now

---------

Co-authored-by: EdwardAngert <17991901+EdwardAngert@users.noreply.github.com>
This commit is contained in:
Edward Angert
2025-06-16 13:18:55 -04:00
committed by GitHub
co-authored by EdwardAngert
parent 095007766b
commit 5c16079aff
19 changed files with 362 additions and 117 deletions
+6 -31
View File
@@ -304,7 +304,7 @@ Visit the Coder UI to confirm these changes:
```env
# Depending on your identity provider configuration, you may need to explicitly request a "roles" scope
CODER_OIDC_SCOPES=openid,profile,email,roles
CODER_OIDC_SCOPES=openid,profile,email,offline_access,roles
# The following fields are required for role sync:
CODER_OIDC_USER_ROLE_FIELD=roles
@@ -517,7 +517,7 @@ Steps to troubleshoot.
## Provider-Specific Guides
Below are some details specific to individual OIDC providers.
<div class="tabs">
### Active Directory Federation Services (ADFS)
@@ -577,33 +577,8 @@ Below are some details specific to individual OIDC providers.
groups claim field.
Use [this answer from Stack Overflow](https://stackoverflow.com/a/55570286) for an example.
### Keycloak
## Next Steps
The `access_type` parameter has two possible values: `online` and `offline`.
By default, the value is set to `offline`.
This means that when a user authenticates using OIDC, the application requests
offline access to the user's resources, including the ability to refresh access
tokens without requiring the user to reauthenticate.
To enable the `offline_access` scope which allows for the refresh token
functionality, you need to add it to the list of requested scopes during the
authentication flow.
Including the `offline_access` scope in the requested scopes ensures that the
user is granted the necessary permissions to obtain refresh tokens.
By combining the `{"access_type":"offline"}` parameter in the OIDC Auth URL with
the `offline_access` scope, you can achieve the desired behavior of obtaining
refresh tokens for offline access to the user's resources.
### Google
To ensure Coder receives a refresh token when users authenticate with Google
directly, set the `prompt` to `consent` in the auth URL parameters. Without
this, users will be logged out after 1 hour.
In your Coder configuration:
```shell
CODER_OIDC_AUTH_URL_PARAMS='{"access_type": "offline", "prompt": "consent"}'
```
- [Configure OIDC Refresh Tokens](./oidc-auth/refresh-tokens.md)
- [Organizations](./organizations.md)
- [Groups & Roles](./groups-roles.md)